PT-2023-5168 · Microsoft+1 · Windows+1

CVE-2023-38558

·

Publicado

2023-09-14

·

Atualizado

2023-09-20

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC PCS neo (Administration Console) versions V4.0 through V4.0 Update 1
Description The issue is related to a leak of information about files and directories in the administration console of the SIMATIC PCS neo system, which can lead to the exposure of Windows admin credentials. An attacker with local access to the Administration Console could exploit this to gain admin access to other Windows systems by impersonating the admin user.
Recommendations For SIMATIC PCS neo (Administration Console) versions V4.0 through V4.0 Update 1, consider restricting local access to the Administration Console to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the use of the Administration Console to necessary personnel only, to reduce the potential for unauthorized access.

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05760
CVE-2023-38558

Produtos afetados

Simatic Pcs Neo
Windows